Crunchyroll
Incident posture
Linked entities
- Victim
- Crunchyroll
- Threat actors
- 0 actors
- Sources
- 3 sources
Timeline
Summary
Crunchyroll faced claims of a cyberattack involving its outsourcing partner Telus, with threat actors alleging that malware infection granted access to customer systems and enabled the exfiltration of about 100 gigabytes of personally identifiable information including IP addresses, email addresses, credit card details and ticketing analytics. The service stated that its investigation is ongoing, that at present the information appears limited to customer service ticket data, and that it has seen no evidence of continued access to its networks. According to the threat actor, access was revoked after roughly twenty‑four hours, though the service has not publicly confirmed a breach and has not responded to requests for comment, while also noting a previous class‑action lawsuit concerning alleged unauthorized sharing of user viewing data.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On March 12, 2026, a threat actor claimed to have gained access to Crunchyroll’s systems through a compromised employee at Telus, the company’s outsourcing partner that provides digital operational support services. The actor stated that malware executed on the Telus employee’s workstation provided a foothold into Crunchyroll’s internal environment, allowing lateral movement into customer‑facing systems such as the ticketing infrastructure. According to the threat actor, the intrusion occurred on that date and remained active for approximately 24 hours before Crunchyroll reportedly detected and revoked the unauthorized access. The actor further claimed that during this window roughly 100 gigabytes of personally identifiable information were exfiltrated from Crunchyroll’s customer analytics environment and ticketing system.
The alleged data set described by the threat actor included IP addresses, email addresses, credit card details, and broader customer analytics data, all of which could enable identity theft, financial fraud, and targeted phishing campaigns if misused. A separate report from Cyber Security News echoed the claim that the breach originated via Telus and noted that the bad actor asserted access to billing information, email addresses, and IP addresses. Crunchyroll has not publicly confirmed the breach, and as of the March 23, 2026 publication of the Cyber Security News article, the company had not acknowledged the incident or responded to requests for comment. The threat actor also asserted that Crunchyroll ignored all communications regarding the incident and made no public disclosure to affected subscribers.
In response to the circulating rumors, Crunchyroll issued statements on March 23 and March 24, 2026, indicating awareness of the claims and saying it was working closely with leading cybersecurity experts to investigate the matter. A spokesperson said the investigation was ongoing and that, at that time, the company believed any exposed information was primarily limited to customer service ticket data stemming from an incident with a third‑party vendor. Crunchyroll stated it had found no evidence of ongoing access to its systems and was continuing to monitor the situation closely. The allegations come amid a pre‑existing class‑action lawsuit filed in early 2026 concerning Crunchyroll’s alleged unauthorized sharing of user viewing data with third‑party marketing platforms.
Sources
Sources available to members: 3 sources.